IT
56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1342 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1315, CVE-2019-1339. 1.2%
CVE-2018-8329 HIGH 7.8 microsoft windows_10 An Elevation of Privilege vulnerability exists in Windows Subsystem for Linux when it fails to properly handle objects in memory, aka "Linux On Windows Elevation Of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. 1.2%
CVE-2025-66389 HIGH 7.5 microsoft github_copilot GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection. 1.2%
CVE-2026-58627 HIGH 7.5 microsoft windows_10_1607 Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50647 HIGH 7.5 microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50496 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. 1.2%
CVE-2026-50424 HIGH 7.5 microsoft windows_11_24h2 Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50411 HIGH 7.5 microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50368 HIGH 7.5 microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50355 HIGH 7.5 microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50304 HIGH 7.5 microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-54983 HIGH 7.5 microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-54119 HIGH 7.5 microsoft windows_10_1607 Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50696 HIGH 7.5 microsoft windows_10_1809 Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50695 HIGH 7.5 microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50653 HIGH 7.5 microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-50506 HIGH 7.5 microsoft asp.net_core_odata Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-49788 HIGH 7.5 microsoft windows_10_1607 Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-49787 HIGH 7.5 microsoft windows_10_1607 Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-45646 HIGH 7.5 microsoft asp.net_core_odata Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-44806 MED 5.3 microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2026-40378 HIGH 7.5 microsoft windows_10_1607 Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2023-29335 HIGH 7.5 microsoft 365_apps Microsoft Word Security Feature Bypass Vulnerability 1.2%
CVE-2018-8219 HIGH 8.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to properly enforce privilege levels, aka "Hypervisor Code Integrity Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 1.2%
CVE-2018-0809 HIGH 7.0 microsoft windows_10 The Windows kernel in Windows 10, versions 1703 and 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability". This CVE is unique from 1.2%